CVE-2020-1934
published 2020-04-01CVE-2020-1934: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
PriorityP345medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
51.95%
98.8th percentile
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_http_server | — | — |
| apache | http_server | 2.4.0 – 2.4.41 | — |
| apache | httpd | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.4.43-1 (bookworm) | apache2 2.4.43-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_route_manager | — | — |
| oracle | communications_session_route_manager | — | — |
| oracle | communications_session_route_manager | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | instantis_enterprisetrack | 17.1 – 17.3 | — |
| oracle | zfs_storage_appliance_kit | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via mod_proxy_ftp when Apache HTTP Server proxies requests to a malicious FTP backend server; monitor for unexpected FTP proxy traffic through Apache. ↗
- →The attack vector is remote over HTTP; a remote attacker could exploit this to obtain sensitive information (uninitialized memory disclosure) via a malicious FTP backend. ↗
- ·Affected Apache HTTP Server versions are 2.4.0 through 2.4.41; the fix is included in 2.4.42 and later. Ensure mod_proxy_ftp is disabled if FTP proxying is not required. ↗
- ·Red Hat JBoss Enterprise Web Server 2 is not affected; Red Hat Enterprise Linux 5 and 6 are out of support scope; Red Hat Software Collections fix was deferred at time of advisory. ↗
- ·The vulnerability is caused by use of an uninitialized memory variable; in most cases there is no practical impact, but corner cases may allow remote reading of memory contents. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_apache5.3LOW
vendor_debian5.3LOW
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2020-08-13·CVSS 9.8
CVE-2020-9490 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Fabrice Perez discovered that the Apache mod_rewrite module incorrectly
handled certain redirects. A remote attacker could possibly use this issue
to perform redirects to an unexpected URL. (CVE-2020-1927)
Chamal De Silva discovered that the Apache mod_proxy_ftp module incorrectly
handled memory when proxying to a malicious FTP server. A remote attacker
could possibly use this issue to obtain sensitive information.
(CVE-2020-1934)
Felix Wilhelm discovered that the HTTP/2 implementation in Apache did not
properly handle certain Cache-Digest headers. A remote attacker could
possibly use this issue to cause Apache to crash, resulting in a denial of
service. This issue only affected
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2020-1934
vendor_oracle·2020-07-15·CVSS 5.3
CVE-2020-1934 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2020-1934
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) vulnerability
CVE: CVE-2020-1934
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
httpd: mod_proxy_ftp use of uninitialized value
vendor_redhat·2020-04-01·CVSS 5.3
CVE-2020-1934 [MEDIUM] CWE-456 httpd: mod_proxy_ftp use of uninitialized value
httpd: mod_proxy_ftp use of uninitialized value
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
A flaw was found in Apache's HTTP server (httpd) .The mod_proxy_ftp module may use uninitialized memory with proxying to a malicious FTP server. The highest threat from this vulnerability is to data confidentiality.
Statement: This flaw is caused by use of an uninitialized memory variable. Practically this has no impact, but in some corner cases it is possible that the contents of this variable could be read by a remote process, causing loss of confidentiality as a result of this. There is no evidence of code execution.
Package: httpd (Red Hat Enterprise Linux 5) - Out of support scope
Package: httpd (Red Hat Enterpr
Debian
CVE-2020-1934: apache2 - In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memor...
vendor_debian·2020·CVSS 5.3
CVE-2020-1934 [MEDIUM] CVE-2020-1934: apache2 - In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memor...
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
Scope: local
bookworm: resolved (fixed in 2.4.43-1)
bullseye: resolved (fixed in 2.4.43-1)
forky: resolved (fixed in 2.4.43-1)
sid: resolved (fixed in 2.4.43-1)
trixie: resolved (fixed in 2.4.43-1)
Apache
Apache httpd: CVE-2020-1934
vendor_apache·CVSS 5.3
CVE-2020-1934 [LOW] Apache httpd: CVE-2020-1934
Apache httpd: CVE-2020-1934
in Apache HTTP Server versions 2.4.0 to 2.4.41, mod_proxy_ftp use of uninitialized value with malicious FTP backend. Acknowledgements: The issue was discovered by Chamal De Silva Reported to security team 2020-01-03 Issue public 2020-04-01 Update 2.4.42 released 2020-04-01 Affects 2.4.41, 2.4.40, 2.4.39, 2.4.38, 2.4.37, 2.4.35, 2.4.34, 2.4.33, 2.4.30, 2.4.29, 2.4.28, 2.4.27, 2.4.26, 2.4.25, 2.4.23, 2.4.20, 2.4.18, 2.4.17, 2.4.16, 2.4.12, 2.4.10, 2.4.9, 2.4.7, 2.4.6, 2.4.4, 2.4.3, 2.4.2, 2.4.1, 2.4.0
Severity: low
GHSA
GHSA-x5pm-xqw2-5256: In Apache HTTP Server 2
ghsa_unreviewed·2022-05-24
CVE-2020-1934 [HIGH] CWE-908 GHSA-x5pm-xqw2-5256: In Apache HTTP Server 2
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
OSV
apache2 vulnerabilities
osv·2020-08-13·CVSS 9.8
CVE-2020-1927 [CRITICAL] apache2 vulnerabilities
apache2 vulnerabilities
Fabrice Perez discovered that the Apache mod_rewrite module incorrectly
handled certain redirects. A remote attacker could possibly use this issue
to perform redirects to an unexpected URL. (CVE-2020-1927)
Chamal De Silva discovered that the Apache mod_proxy_ftp module incorrectly
handled memory when proxying to a malicious FTP server. A remote attacker
could possibly use this issue to obtain sensitive information.
(CVE-2020-1934)
Felix Wilhelm discovered that the HTTP/2 implementation in Apache did not
properly handle certain Cache-Digest headers. A remote attacker could
possibly use this issue to cause Apache to crash, resulting in a denial of
service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-9490)
Felix Wilhelm discovered that
OSV
CVE-2020-1934: In Apache HTTP Server 2
osv·2020-04-01·CVSS 5.3
CVE-2020-1934 [MEDIUM] CVE-2020-1934: In Apache HTTP Server 2
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
No detection rules found.
No public exploits indexed.
HackerOne
Use of uninitialized value in ftp_getrc_msg method of mod_proxy_ftp.c
hackerone·2020-10-10·CVSS 5.3
[MEDIUM] Use of uninitialized value in ftp_getrc_msg method of mod_proxy_ftp.c
Use of uninitialized value in ftp_getrc_msg method of mod_proxy_ftp.c
This is a Security Bug Report for mod_proxy_ftp. This bug is present in ftp_getrc_msg method of modules/proxy/mod_proxy_ftp.c file.
This is the line which causes this bug.
```c
...
mb = apr_cpystrn(mb, response + 4, me - mb);
...
```
If ftp server returns a response like "\r\n", which has 3 characters with terminating NULL byte, apr_cpystrn method will copy uninitialized values.
Because that line uses "response + 4" as the source of data for apr_cpystrn method.
Apache Http Server version: 2.4.41
CVE-ID: [CVE-2020-1934](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1934)
Apache Http server fixed security bugs: (https://httpd.apache.org/security/vulnerabilities_24.html)
Steps to reproduce
Python 3 and Ubuntu
Bugzilla
CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value [fedora-all]
bugzilla·2020-04-03·CVSS 5.3
CVE-2020-1934 [MEDIUM] CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value [fedora-all]
CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value
bugzilla·2020-04-03·CVSS 5.3
CVE-2020-1934 [MEDIUM] CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value
CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
Reference:
https://httpd.apache.org/security/vulnerabilities_24.html
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 1820776]
---
External References:
https://httpd.apache.org/security/vulnerabilities_24.html
---
Upstream patch: https://svn.apache.org/viewvc?view=revision&revision=1873745
---
Statement:
This flaw is caused by use of an uninitialized memory variable. Practically this has no impact, but in some corner cases it is possible that the contents of this variable could be read by a remote process, causing loss of confidentiality as a result of this. There
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.htmlhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r09bb998baee74a2c316446bd1a41ae7f8d7049d09d9ff991471e8775%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r1719675306dfbeaceff3dc63ccad3de2d5615919ca3c13276948b9ac%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r26706d75f6b9080ca6a29955aeb8de98ec71bbea6e9f05809c46bca4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r33e626224386d2851a83c352f784ba90dedee5dc7fcfcc221d5d7527%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r52a52fd60a258f5999a8fa5424b30d9fd795885f9ff4828d889cd201%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5d12ffc80685b0df1d6801e68000a7707dd694fe32e4f221de67c210%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdf3e5d0a5f5c3d90d6013bccc6c4d5af59cf1f8c8dea5d9a283d13ce%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A2RN46PRBJE7E7OPD4YZX5SVWV5QKGV5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYVYE2ZERFXDV6RMKK3I5SDSDQLPSEIQ/https://security.netapp.com/advisory/ntap-20200413-0002/https://usn.ubuntu.com/4458-1/https://www.debian.org/security/2020/dsa-4757https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.htmlhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r09bb998baee74a2c316446bd1a41ae7f8d7049d09d9ff991471e8775%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r1719675306dfbeaceff3dc63ccad3de2d5615919ca3c13276948b9ac%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r26706d75f6b9080ca6a29955aeb8de98ec71bbea6e9f05809c46bca4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r33e626224386d2851a83c352f784ba90dedee5dc7fcfcc221d5d7527%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r52a52fd60a258f5999a8fa5424b30d9fd795885f9ff4828d889cd201%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5d12ffc80685b0df1d6801e68000a7707dd694fe32e4f221de67c210%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdf3e5d0a5f5c3d90d6013bccc6c4d5af59cf1f8c8dea5d9a283d13ce%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A2RN46PRBJE7E7OPD4YZX5SVWV5QKGV5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYVYE2ZERFXDV6RMKK3I5SDSDQLPSEIQ/https://security.netapp.com/advisory/ntap-20200413-0002/https://usn.ubuntu.com/4458-1/https://www.debian.org/security/2020/dsa-4757https://www.oracle.com/security-alerts/cpujul2020.html
2020-04-01
Published